What we collect, why, and who else touches it. Short, because there is not much to say: no PHI, no advertising, no data sales.
RecCheckMD, LLC (“RecCheckMD”, “we”) is a Tennessee limited liability company. This policy explains what information we collect when you use www.reccheckmd.com and the RecCheckMD service, how we use it, and the choices you have. If your organization has a signed agreement with us, that agreement governs our handling of your organization’s data where the two differ.
Your name and work email address, provided when you sign in. Sign-in is handled by Auth0; we never see or store your password. We also record when you signed in and, for the audit trail, the actions you take in the service.
When you request a demo we collect your name, work email, organization, an optional phone number, and, if you arrived from a campaign link, which campaign.
Standard server logs and page-view records. For analytics we keep the page visited and a one-way hash of the IP address, not the address itself. Requests from automated crawlers are excluded.
We set a signed session cookie (HttpOnly, Secure), a CSRF-protection cookie, and a short-lived sign-in state cookie during the Auth0 hand-off. Browser storage holds per-device preferences such as dismissed banners and your assistant conversation. We use no advertising cookies and no third-party analytics trackers.
We do not sell personal information and we do not use your data for advertising.
The Echo assistant and the recall-notice reader send the relevant text, and for photographed notices the image, to Anthropic’s API to produce a response. Only the data needed for that request is sent, and it is used to generate the response under Anthropic’s commercial API terms. You can use RecCheckMD without these features.
We share data only with the service providers that run RecCheckMD, and only for the purpose listed:
| Provider | Purpose | Data involved |
|---|---|---|
| Auth0 (Okta) | Sign-in and account identity | Name, email, sign-in events |
| Railway | Application hosting and the database (United States) | All service data |
| Cloudflare R2 | File storage for uploaded files, reports, and forwarded notices | Uploaded files and generated reports |
| Resend | Email delivery | Recipient address and the email content |
| Anthropic | AI assistant and notice reading | Text and images for the specific request |
| U.S. FDA (openFDA, accessdata.fda.gov) | Public recall data and device identity lookups | Product identifiers used in a lookup |
| DuckDuckGo | Product image lookup on alert cards | Product name and manufacturer |
| Google Fonts, jsDelivr | Fonts and a charting library loaded by your browser | Your browser’s standard request headers |
We may also disclose information when required by law or to protect the security of the service, with notice to you where the law permits.
How we protect your data is described on our Security page. If we confirm a security incident involving unauthorized access to your organization’s data, we will notify your organization without undue delay and within seventy-two hours.
RecCheckMD is built for healthcare organizations in the United States and is not directed at children under 18.
We will post changes to this policy here and update the date above. For questions or requests, write to info@reccheckmd.com.